Caveat 7.23.26
Ep 317 | 7.23.26

AI’s political and copyright reckoning.

Transcript

Dave Bittner: Hello, everyone, and welcome to "Caveat," N2K CyberWire's privacy, surveillance, law, and policy podcast. I'm Dave Bittner. Joining me is my co-host, Ben Yelin, from the University of Maryland Center for Cyber, Health, and Hazard Strategies. Hey there, Ben.

Ben Yelin: Hello, Dave.

Dave Bittner: On today's show, Ben discusses how political candidates are trying to manipulate AI chatbots, and I've got a look at copyright law in the age of AI. While this show covers legal topics, and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, let's kick things off here. What do you got for us?

Ben Yelin: This is a fun story. You know, sometimes we don't want to take ourselves too seriously, so this is kind of the dessert, if you think of our other stories as eating our vegetables.

Dave Bittner: Okay.

Ben Yelin: The story comes from the New York Times, politicians are trying to change what chatbots say about them, and the hook is there's a Democratic candidate for the Missouri State Legislature named Dustin Lloyd, and he figured out that AI chatbots knew little about him beyond kind of basic public information. They didn't know what his policy priorities were, and this is bad for him because, especially in lower-profile political races, people are going to increasingly be using chatbots to get information. I mean, it's the new Google, and you can think of Google as kind of a chatbot if you're doing a search and Gemini generates something and you have questions about it.

Dave Bittner: More and more.

Ben Yelin: Yeah, exactly, so this is the new frontier, and if you are trying to make a name for yourself in politics, you have to make sure that the chatbot's answers are favorable to you.

Dave Bittner: Right.

Ben Yelin: What he did is he changed the information on his own campaign website, included a long question and answer section about his background and goals, and when he did that, he found that chatbot responses became more detailed and aligned with the message he wanted voters to hear. Part of his campaign strategy is figuring out what to put on his website so that AI chatbots portray him in a positive light, and this is really about reputation management. I think it used to be that political campaigns were focusing on social media and search engine optimization. The new frontier here is because of how AI systems synthesize information, voters can treat these chatbot responses as authoritative. We have kind of an automation bias. If we see that a chatbot says something, it at least appears to us as being trustworthy. The other side of this, though, is that now that we know that people are manipulating their own websites and potentially other websites to manipulate these AI chatbots, I think we should have a lesser trust in what these chatbots are telling us about these candidates because the candidates themselves could be feeding in information. The other thing is campaigns that have more money or more resources may be able to gain kind of an unfair advantage here because they can use staffers, people with technical expertise, to figure out better strategic messaging. It could kind of have an undue influence on how voters evaluate candidates and campaigns in the future. One thing that was really striking to me about this is how quickly this all happens. They've done experiments. Basically, if you update your campaign page with key facts about such and such candidate and then kind of search or ask the chatbot questions every couple of minutes, it takes about 12 minutes in their estimation for that information to make it into the chatbot. The lesson here is this: If you are using a chatbot to learn about political candidates, just know that there might be a candidate behind the curtain who is manipulating that chatbot to be more favorable. This is kind of the new thing in the 2026 election cycle.

Dave Bittner: Well, I can imagine that Mr. Lloyd's adversaries could do the same thing, right? I could envision someone posting a web page that is white text on a white background, so invisible to the human eye, but has all kinds of negative information and attacks on a particular candidate in the same way they try to flood the chatbots with that and influence them that way.

Ben Yelin: Totally. With opposition research, you can do things that are very obvious, but you might get caught. If you're trying to edit the candidate's Wikipedia page which, believe me, opposition researchers do that all the time. It doesn't always work. Wikipedia doesn't always accept the edits, but if you're, like, so-and-so is a philandering racist and put that on their Wikipedia profile, that's a great way to have the chatbot return negative material, but if you're more shrewd about it and do it in less visible ways -- just like the way you're describing -- you might be successful. Even something, like, having a website with your opposition's name on it that's just filled with negative facts about them could be a way to offset somebody trying to put positive information on their own website. It could be a war of AI chatbot optimization, where the side that's able to effectively put the most stuff out there ends up winning, regardless of what the truth actually is.

Dave Bittner: I mean, it's kind of the next generation of search engine optimization, right? That's what it sounds like.

Ben Yelin: It is. Yeah, there are now businesses that do AI, I guess they're calling it AEO, so AI Engine Optimization.

Dave Bittner: Of course they are, right?

Ben Yelin: Actually, Answer Engine Optimization is the official term here.

Dave Bittner: Okay.

Ben Yelin: That's a way to change how AI chatbots generate their answers about a person. The other thing is, like, you don't have to just do it on your own campaign website or on Wikipedia. You can just, like, start a Reddit thread that's, like, "such and such candidate." Then write a bunch of positive things. Just the nature of where chatbots search to find information, if that ends up really making it quickly into the chatbot answer, the chatbot responds. It does feel to me like it's kind of fundamentally dishonest because you're gaming the system, but then again, is there really a totally unbiased, fair way of people to get information about a candidate? It's not like in the absence of AI chatbots, people would be reading their local newspapers, candidate by candidate profile.

Dave Bittner: Kind of like the League of Women Voters Voter's Guide.

Ben Yelin: That's how things worked in the 1980s. Right now, the alternative is a Google search when you're doing search engine optimization, or kind of random stuff you're reading on social media, which somehow is even more untrustworthy and unreliable than chatbot responses. If this is the game we're going to be playing, I think candidates are increasingly going to realize that they have to play this game.

Dave Bittner: You know, it also reminds me, I have a colleague who runs a website that has a bunch of information that he wants to share publicly, just kind of something that provides information for the public good, and he's been saying how it's really hard to keep the site up and running because it just gets hammered every day by all of these AI scrapers, and he has to pay for the bandwidth. It takes up so much of his time trying to block these scrapers, and of course, the scrapers know this, so they're using -- what do they call them -- residential proxies, where they look like they're coming from someone's home rather than from a big data center to try to trick the website into allowing them to scrape the information, and they're very effective at that.

Ben Yelin: And the website owner gets nothing out of this transaction, right?

Dave Bittner: Right. It's not like the old days where Google would scrape you and then you'd get linkbacks.

Ben Yelin: Right, you get nothing.

Dave Bittner: They'd give you traffic, yeah.

Ben Yelin: I wonder how long this equilibrium can continue, because eventually, like, people are just going to stop putting useful information on these websites if they're just going to be scraped so that we can't reap the rewards of our own creativity.

Dave Bittner: Right.

Ben Yelin: I just wonder how far away we are from that. Also, in the political context, given that we just have basically no campaign finance laws in this country. I don't think there are going to be rules against doing something like this. I think eventually, once the public realizes what's going on and it reaches a critical mass of, you shouldn't believe the responses from chatbots because candidates are manipulating them, I think we'll reach that critical mass where at a certain point it becomes untrustworthy. I don't think we're there yet. I think people are -- and I caught myself doing it myself -- just times when I probably shouldn't be trusting a chatbot, and I just do because it seems so authoritative. I can see why this would work with other people, even though it is so prone to manipulation. All it's doing is it's just much better than you at searching the internet. It can do it much quicker than you can. If it takes me 20 minutes to find information about a candidate, it takes my chatbot 0.0001 seconds to do it, but that's really all it's doing. It's not going into the minds of these candidates and trying to inform us about who would be better on X, Y, Z issues.

Dave Bittner: Yeah, I mean, my recommendation for people is to kind of calibrate your relationship with these is ask it for a biography of someone famous that you have a lot of knowledge about, that you are authoritative about, right? I think we all have people in our lives that we're either fans of, and it can be a musician or an actor or a writer or whoever, a politician, a president. Ask the chatbot for a biography and see how often it is wrong, because it will be.

Ben Yelin: If you even have any semblance of a public profile, search yourself. They're making predictions about you based on the very little information that they can find. I don't have much of a public presence. You can find me on LinkedIn. You can find me on my organization's website. If you ask ChatGPT or Claude, "Who is Ben Yelin?" you'll get some answers where they really extrapolate a lot and might say things that aren't entirely accurate.

Dave Bittner: What tends to happen with me is, because I'm pretty public facing in my job, it will often credit me for hosting security podcasts that I do not host.

Ben Yelin: Right, the best kind of hallucinations.

Dave Bittner: It'll put me hosting shows that are our friendly competitors but that I have nothing to do with, and that's routine for it to do that, to lump me in with other shows.

Ben Yelin: If a chatbot says that, are you allowed to put it on your resume? Like, Dave hosts the top ten cyber-related podcasts.

Dave Bittner: That's right. He's the host of every popular cyber-security-related podcast, so sayeth ChatGPT.

Ben Yelin: My authoritative ChatGPT, yep.

Dave Bittner: Well, I think this whole story brings up something else that I've been pondering over the past week or so. I saw a story about slop biographies that are being written.

Ben Yelin: Yes.

Dave Bittner: I can't remember any of the specific names, but what prompted the article that I read was someone sent an email to their friend and said, "Hey, I saw this biography of you was just published." They went, "What?"

Ben Yelin: Yep.

Dave Bittner: They had no idea. Somebody ran, someone who's noteworthy, through a chatbot, and it wrote a biography, a book-length biography, which they then published via Amazon self-publishing, and now you can buy a printed hardcover book of this biography.

Ben Yelin: I can't wait to write and purchase the Dave Bittner biography.

Dave Bittner: Right.

Ben Yelin: I'm going to be a millionaire.

Dave Bittner: Well, don't get ahead of yourself.

Ben Yelin: All right. All right. I'll slow my roll here.

Dave Bittner: Yeah, it's a shame. You know, my mom's passed away. That would have been one guaranteed purchase for you. My line of thinking was, what happens when these books, these slop books, end up on the bookshelf at the library, and in doing so, become authoritative? Where do we find our facts? When I was a kid growing up, we had the encyclopedia. You'd go to the library. You'd look something up. You'd go to the dictionary. Look something up. Now, everybody looks things up online. Obviously, there are pluses to it. I mean, Wikipedia is better than any encyclopedia you have sitting on the shelf, it covers everything, but as we're talking about here, the flip side is, what becomes accepted truth?

Ben Yelin: With Encyclopedia Britannica, you couldn't just, like, go into their giant repository with a permanent marker, cross things out, and, like, write your own story.

Dave Bittner: Right, and have it update every encyclopedia that was sitting on every bookshelf, right?

Ben Yelin: Instantly.

Dave Bittner: Yeah.

Ben Yelin: Yeah, I think it's a huge problem. I mean, also, once these things get spread around, they become universal truth. You write some fake information about a candidate somewhere, then that goes to one chatbot, and then chatbots are learning from one another, and that answer shows up on the internet. Somebody writes about it in a Reddit post, another chatbot finds it, and eventually, that becomes the established truth. That's a big problem. If you're a political candidate, you might be getting temporary gains from doing something like this, but I think the long-term costs of having this ability to kind of work the refs on what chatbots are saying about you could certainly have downsides.

Dave Bittner: I was also thinking about, like, there are common -- let's call them myths. George Washington probably did not cut down the cherry tree, right?

Ben Yelin: I hate to hear that because I just want to believe.

Dave Bittner: Yeah. Yeah, there's one local here where you and I live. There's a little mill town called Ellicott City, and one of the things that they're famous for is having the oldest train station in the United States.

Ben Yelin: Not functioning, by the way.

Dave Bittner: Not functioning now.

Ben Yelin: You can't actually take a train there.

Dave Bittner: You can't. It's a museum now, and a lovely one, so I do recommend, if you're in the area, go check it out. There was a famous historical event that took place which was the Race of the Tom Thumb, which was a steam-powered engine, and it raced against a horse, and it was a historic thing. A friend of mine, who's a documentary filmmaker, was working for the local historical society and was researching this, found out it probably never happened, and so what do you do? Legend is there. It's known all over, so in his documentary, he had to use phrasing, like, you know, "Legend has it that this occurred," you know? I don't know. Again, I was just sort of thinking, like, what's the logical conclusion to this? What's the tail? There's the snake that eats his tail, Ouroboros, right?

Ben Yelin: Oh, yeah.

Dave Bittner: Where information is being accepted as authoritative, and then it just loops back on itself.

Ben Yelin: You know, going through the passage of time, this has always been a bit of a problem, even, like, people passing stories down from generation to generation.

Dave Bittner: Right, the victor writes the history, right?

Ben Yelin: Exactly, or it's kind of a game of telephone, where certain things get lost in translation. I mean, I've seen people, like, expound on that when it comes to the Bible. Like, this is what it said when it was in Aramaic, and this is -- eventually through translations, it became something a little bit different. To a certain extent, that's already existed. I think the difference now is just the scale, and everybody is a storyteller, so it's not just the victors get to tell the story. So, like, it's not only information that might be potentially unreliable. It's possibly conflicting information because everybody's fighting against one another to game these chatbots.

Dave Bittner: Yeah.

Ben Yelin: It's kind of a -- like, I wish that wasn't the incentive structure, especially when we're talking about politics, because we're setting out to destroy people's reputations here. I mean, politics is a tough game. It's kind of -- I wish all of this was just focused on a legitimate search for the truth, but I think we have to recognize that that's not really how it works.

Dave Bittner: Yeah. Yeah, well, we'll have a link to that story in the show notes. I'll tell you what. Let's take a quick break here. We'll be right back after these messages. [ Music ] We are back. I guess my story isn't completely unrelated to yours.

Ben Yelin: Oh, there we go.

Dave Bittner: This is from a publication out of the UK called The Dial. This is written by Zoe Forbes, who is a writer and lawyer in the UK. This story is -- comes from a UK-centric point of view, but I think the things that they're talking about apply here. It's really looking at copyright law and intellectual property and how all of that is facing up to the reality in which we live with all these AI chatbots. The ingestion of all these things and how organizations are trying to fight it and what they may and may not have success with. This article talks about Getty Images, which of course is a huge stock image photo library, probably one of the biggest in the world, certainly one of the most well-known. Back in 2022, Stability AI released their Stable Diffusion product, which enabled AI image generation, which I think we're all familiar with now.

Ben Yelin: Yeah, I use it probably too frequently, mostly to make fun of friends and colleagues, you know?

Dave Bittner: Yeah, but all these models have to be trained. One of the things that Stable Diffusion was trained on was Getty's Image Library. Allegedly, billions of images were scraped without permission. Getty sued. They sued Stability in the UK in 2023 for copyright and trademark infringement. They were not successful there. The judge in the UK said, the scraping didn't happen here; it happened in the US, so go fight them there. They are. They're still in the midst of that battle over trying to exert their copyright rights in the US There's a few interesting aspects here. There's this notion of, if training is truly copyright infringement, and I always use the analogy of, if I go and walk around inside a museum and take in everything that I see, and then I go home and I paint something inspired by --

Ben Yelin: Paint your version of Picasso?

Dave Bittner: Yeah, have I violated the copyright of everything in that museum? I would argue no.

Ben Yelin: I agree, yeah.

Dave Bittner: This article also points out for authors, people who are writing books and things like that, their information has been scraped, and there's no protection for them against an AI being asked to write in the style of a particular author. There was a case here they mentioned where -- I think it was Grammarly -- was allowing you to have your writing critiqued by someone who was in the style of a famous writer. In other words, I could write a scary story and have it critiqued by Stephen King.

Ben Yelin: Right, right.

Dave Bittner: Or an AI that was trained in the style of Stephen King.

Ben Yelin: He's a very public Twitter user, so we can tell what his attitude is pretty easily. I'm sure that's easy to scrape.

Dave Bittner: Right, but of course, some of the authors didn't take kindly to this, and they've sued Grammarly over this. I said, there's nothing that protects an author or an artist from someone doing something in the style of what they do, but there are laws that protect, they refer to it as the personality of the person. Whether or not these folks have a case for someone imitating them for critiquing purposes is yet to be determined. Before I go any further with this, let me just check in with you, Ben, what's your take so far?

Ben Yelin: Yeah, I mean, I think you've identified the central problem here, which is how do we define a copyright when it's not literally copying the creative work? It's not extrapolating someone's writing exactly and using it to -- passing it off as one's own and using it to make some type of profit. It's not literally that. Our legal system has had a hard time, not just our legal system, but legal system in the European Union, figuring out what goes too far. I think in the pre-AI context, generating images or writing that was in the style of somebody else seems prima facie evidence that it's not a copyright violation. AI does this to such a degree where you're really able to compile images and writing instantaneously millions of different times. It's so effortless on the part of the user. In some ways, I feel like it's appropriating the time that the person has used to develop their creative works. If an author takes 20 years to develop their own unique writing style through toil and hard work, and then somebody can just write in the style of Stephen King and can produce something and try and pass it off as one's own, maybe that doesn't violate the letter of our copyright law, but it violates the spirit of our copyright law. That's a problem I just don't really know how to solve. AI companies, I think, have really decent arguments about this, that copying facts, ideas, and patterns are generally not protected by copyright law. All AI chatbots or LLMs, all they're doing, or image generators, are learning statistical relationships rather than literally storing the copyrighted material. I think that's pretty compelling. I think it's incumbent upon policy makers to try and carve out some type of legal regime where the original author merits at least some degree of protection. I talked about a couple of examples from Europe where you can allow limited copying without permission. These are kind of changes to common law copyright, sort of historical copyright case law. Maybe there can be a meeting of the minds between AI developers and people representing artists and writers to try and reach some middle ground on this, but I think we're a long way off from that.

Dave Bittner: There was another aspect here, I guess I'd call it a "legal term of art" that was suggested could be pursued by one of the judges who is hearing one of these cases. It was actually a case against Meta. The judge suggested that they should pursue market dilution as their angle here, which is the idea that it's not so much that they're copying the works, it's that they're making the works less valuable by flooding the market with comparable works. There was another judge who wasn't so into that idea, and said, basically, something along the lines of, well, should we not train children? Should we not teach a classroom full of children to write because they're just going to grow up to be competitors to the existing authors, right?

Ben Yelin: Right, right.

Dave Bittner: We'd think that's silly, so how does that apply here? I don't know. Not in this article, but another line of thinking, I saw earlier this week was someone was advocating that lawmakers simply carve out AI training as fair use, just be done with it. It's just fair use.

Ben Yelin: Right, at least even if writers and authors and artists wouldn't be happy with that conclusion, at least they'd have an understanding, at least we'd have clarity in the law. We've carved out fair use for a bunch of other things, including things like parody, where it is an extension of the original work, it's just repurposing it into something else. I think that's probably the most likely thing that's going to happen is that this ends up being just categorized as fair use. That's not going to be a satisfying conclusion because I think people will still feel like their intellectual works are being easily manipulated and turned into something else without them getting the credit.

Dave Bittner: Right.

Ben Yelin: Because AI systems feed upon each other, it becomes so attenuated at a certain point you can't track the root of the creativity. If all art becomes derivative through various AI machines over a period of years, at a certain point it's going to become untraceable to the original author. I'm like, that sucks for the original author or artist. I mean, maybe at this point, we're not there yet, but are we going to get to a point where somebody can't be a successful artist because as soon as they create some work, AI is appropriating it and then it's impossible to trace to that artist?

Dave Bittner: Right, right. That was another point they made in this article, that it's making it so much harder for anyone in any sort of creative pursuit to break through because there's so much content out there. How do you set yourself apart when comparable works are being generated endlessly?

Ben Yelin: Right, right, and I don't think there's a good answer to that question. You know, the benefit of fair use is, I think, artists now, for things that are already covered by fair use, artists have an expectation that there are going to be some circumstances in which your writing is used for purposes beyond the original reason you decided to create that work. Having that expectation, I think people can create art or can create music or can create writing within those confines. Maybe that's kind of where we're going to end up here, where people realize they need to be especially creative or they need to leave their mark and make something extra identifiable or extra traceable to them because they know it's going to be used to train AI systems and become unrecognizable. Again, not a satisfying conclusion, but just kind of the equilibrium I see showing up here.

Dave Bittner: Yeah, I guess it's hard to imagine the balance, too, because when you have governments like our own, certainly China, every government at this point is looking at these AI engines as being important for national security. You want to have the best in the world, and how you get the best is by scraping everything, distilling it, and analyzing it and all those things, so how do you reconcile those needs? It's not going to be pretty, even if it might be easy to just say, no, it's fair use.

Ben Yelin: Fair use. Like, that's the best we're going to do. Yeah, I guess the last thing I'll say is, like, we have a long history of copyrighted work becoming easier to access and imitate, and the original creators getting very upset about it and trying to curtail the modes and methods of their works being distributed. We still have people who are doing creative writing. We still have people who are making movies. We still have people who are artists who are creating original works. I think the field is going to survive despite this problem. Ultimately, the ground truth here is somebody's style is not protected under our copyright law. There isn't any -- unless you're using somebody's privacy, private rights or publicity rights, like you're using the author's name or a picture of them, I don't think there really can be a cause of action there. There's nothing in our legal system that would allow that to happen. This is kind of the system that we're stuck with.

Dave Bittner: Right. There's nothing keeping me from writing a novel in the style of Stephen King.

Ben Yelin: Good luck with that, by the way. I'm excited to read it.

Dave Bittner: The point is, if I did and I came up with something that was right on the nose, he would have no action against me, just with imitation being flattery and all that stuff.

Ben Yelin: Yeah. When I was taking guitar lessons, one of the things my guitar teacher said is, "There are only so many chords in music." There have been, actually, a lot of lawsuits over the years complaining that somebody's copying somebody else's music. With few exceptions, all of these cases are dismissed because people gain inspiration from one another. Most pop songs are, like, the same four or five chords in different combinations.

Dave Bittner: Right.

Ben Yelin: That's a special example because there are only a certain number of keys on a piano or a guitar.

Dave Bittner: Right.

Ben Yelin: I think the point still holds that you can't really stop the phenomenon of being inspired by previous works, no matter what form that takes. You just have to kind of exist in that world.

Dave Bittner: Yeah, again, I liken it to if we were a world full of painters and all of a sudden photography came along, right? Just made a particular thing fast and easy and cheap.

Ben Yelin: Totally, and that's literally a thing that did happen. Now, I can't go into an art museum, take a picture of my favorite Picasso, and try and sell it. That would violate copyright law.

Dave Bittner: Well, the piece of art is in the public domain if it's old enough.

Ben Yelin: Yeah, I guess that's true. If it's old enough, it is in the public domain. Okay, I'm going to take pictures of the Mona Lisa and I'm going to try and sell it. I'll see you later.

Dave Bittner: Absolutely. All right. Well, we will have a link to this story in the show notes. Of course, we'd love to hear from you. If there's something you'd like us to consider for the show, please email us. It's caveat@n2k.com. [ Music ] That is our show brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@n2k.com. This episode is produced by Liz Stokes. Our Executive Producer is Jennifer Eiben. The show is mixed by Tré Hester. Peter Kilpe is our Publisher. I'm Dave Bittner.

Ben Yelin: And I'm Ben Yelin.

Dave Bittner: Thanks for listening.